Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2008-3747

Опубликовано: 27 авг. 2008
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 7.5

Описание

The (1) get_edit_post_link and (2) get_edit_comment_link functions in wp-includes/link-template.php in WordPress before 2.6.1 do not force SSL communication in the intended situations, which might allow remote attackers to gain administrative access by sniffing the network for a cookie.

РелизСтатусПримечание
dapper

ignored

end of life, was deferred
devel

not-affected

2.7.1-2ubuntu1
feisty

ignored

end of life, was deferred
gutsy

ignored

end of life, was deferred
hardy

ignored

end of life, was deferred
intrepid

ignored

end of life, was deferred
jaunty

not-affected

2.7.1-2ubuntu1
karmic

not-affected

2.7.1-2ubuntu1
lucid

not-affected

2.7.1-2ubuntu1
maverick

not-affected

2.7.1-2ubuntu1

Показывать по

Ссылки на источники

EPSS

Процентиль: 80%
0.01445
Низкий

7.5 High

CVSS2

Связанные уязвимости

nvd
почти 17 лет назад

The (1) get_edit_post_link and (2) get_edit_comment_link functions in wp-includes/link-template.php in WordPress before 2.6.1 do not force SSL communication in the intended situations, which might allow remote attackers to gain administrative access by sniffing the network for a cookie.

debian
почти 17 лет назад

The (1) get_edit_post_link and (2) get_edit_comment_link functions in ...

github
больше 3 лет назад

The (1) get_edit_post_link and (2) get_edit_comment_link functions in wp-includes/link-template.php in WordPress before 2.6.1 do not force SSL communication in the intended situations, which might allow remote attackers to gain administrative access by sniffing the network for a cookie.

EPSS

Процентиль: 80%
0.01445
Низкий

7.5 High

CVSS2